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I claim: 

1 . A method for providing security to a computer network by monitoring the 
physical location of a network login or login attempt, said method comprising: 

associating a workstation to a physical location; 
associating a network user to said workstation; 

monitoring a computer network to determine a network login or attempted login 

of said user; 

detennining a physical location of said login or attempted login; 
determining whether said user is authorized to access said network from said 
physical location of said login or attempted login. 

2. The method of claim 1 , further comprising determining whether 
preventive action is necessary and, if so, automatically initiating preventive action. 

3 The method of claim 2, wherein said preventive action comprises 

generating an alert. 

4. The method of claim 2, wherein said preventive action comprises 

disconnecting said workstation from said network. 

5. The method of claim 2, wherein said preventive action comprises 
generating a notification message that said user is accessing said computer network from an 

unauthorized location. 

6. The method of claim 1 , further comprising storing information regarding 

said physical location of said login or attempted login. 

7. The method of claim 1 , further comprising storing information regarding 
said workstation associated with said login or attempted login. 
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g. The method of claim 7, wherein said workstation information inclndes one 

or more of the following types of information: an IP/MAC address of said workstation, 

and time of each login attempt, a date and time of eaeh success** login, iogin type description, 

network security agent, domain address, information regarding which net,vork resources were 

accessed, server identification, tire number of login attempts, host name dam, Jack or outlet 

information, port identification, or any other circuit trace information. 

9. The method of claim 1, further comprising generating an event log. 

10. The method of claim 7, wherein said event log comprises infonnation 
regarding said physical location of said login or attempted login and information regarding said 
user. 

11. The method of claim 1 , further comprising associating said user with a 

workstation. 

,2. A method forproviding security to a computer network by monitoring a 
networklogin or login attempt from a particular workstation, saidmethod comprising: 
associating a workstation to a physical location; 
associating a network user to said workstation; 

monitoringacomputer network to determine a network login or attempted login 

of said user; 

determining which workstation said .ogin or attempted login is generated from; 
determining whether said user is authorized to access said network from said 

workstation of said login or attempted login. 

13 . A network security system for a plurality workstations coupled via a local 



a network, said network said security system comprising: 
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electronic storage for associating said workstations to a user and a physical 

location; and 

one or more processors for receiving login Monnation from said workstations 
and accessing said electronic storage to determine whether said user or said workstation is 
authorized to login to said network from said physical location. 

14 The system of claim 13, wherein said one or more processors generates an 

alert based said determination. 

15. The system of claim 14, wherein said alert comprises an email 

notification. 

16. Thesystemofclamil4,whereinsaidalertcomprisesa P agernotification. 

17. The system of claim 14, whereinsaid alert comprises a termination signal. 

18. The system of claim 14, wherein said one or more processors generates an 

event log. 

19. The system of claim 18, wherein said event log comprises atime of said 

access. 

20. The system of claim 18, wherein said event log comprises said physical 

location. 

21. Computer readable medium having computer readable code for causing 
one or more processors to associating a workstation to a physical location; 

associating a network user to said workstation; 

monitoring a computer network to determine a network login or attempted login 

• of said user; 

determining a physical location of said login or attempted login; 
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detemuning whether said user is authorized to aeeess said network from said 
physical location of said login or attempted login. 

22. Anetworkseouritysystemforapluralityworkstationscoupledviaaloeal 

p^tyofda^pomofapatehpaneUsaidpatchpane.fc.hrgcoupleutoaconrputernetwo^ 

said security system comprising: 

a workstation associated with a physical location and a user; 

amonitoring device for determining a network login or attempted login of said 

user, 

a device for determining a physical location of said login or attempted login; 
wherein said system determines whether said user is authorized to access said 
network from said physical location of said login or attempted login. 



